njRAT

MITRE ATT&CK: S0385 View on attack.mitre.org

Aliases: Njw0rm, LV, Bladabindi, Lime-Worm, njRAT

First seen
2012-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
10777 (8816 malicious)
Last IoC activity
2026-09-02 03:33:24
Profile updated
2026-07-07 12:47:46

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:ae country_code:sa country_code:eg

Context

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.

Recent IoC activity

8,822 malicious indicators in Maltiverse are attributed to njRAT (S0385). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 3.64.4.198 2026-09-03 4
IP address 3.141.210.37 2026-09-03 6
IP address 213.152.187.220 2026-09-03 8
IP address 3.141.177.1 2026-09-03 6
IP address 3.127.253.86 2026-09-03 4
IP address 3.69.115.178 2026-09-03 4
IP address 3.68.171.119 2026-09-03 4
IP address 3.127.181.115 2026-09-03 4
IP address 3.125.188.168 2026-09-03 4
IP address 3.126.224.214 2026-09-03 4
file sample de7ce0b4b98abcfcaa736f28f3abce6a4ecc4dc5083bac5c1ef3d3b821618925.exe 2026-09-03 2
hostname comes-corruption.at.ply.gg 2026-09-03 1
hostname mohamednjrat111.no-ip.biz 2026-09-03 1
hostname chromeupdate.servepics.com 2026-09-03 3
hostname teste2018.ddns.net 2026-09-03 1
hostname teaching-wireless.gl.at.ply.gg 2026-09-03 1
hostname jinmo0721.kro.kr 2026-09-03 1
hostname dolaaultra.no-ip.biz 2026-09-03 1
hostname indigo2forjoy.com 2026-09-03 1
hostname hours-morrison.gl.at.ply.gg 2026-09-03 1

Detection coverage

  • 9 YARA rules
  • 637 Sigma rules

Malware & tools used

  • Credentials from Web Browsers (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Video Capture (attack-pattern)
  • Screen Capture (attack-pattern)
  • Native API (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • PowerShell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Compile After Delivery (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Keylogging (attack-pattern)
  • Web Protocols (attack-pattern)
  • Windows Host Firewall (attack-pattern)
  • Clear Persistence (attack-pattern)
  • Modify Registry (attack-pattern)

Used by threat actors

Detection rules

  • SECUINFRA_DROPPER_Njrat_VBS (yara-rule)
  • SECUINFRA_MAL_Njrat (yara-rule)
  • EMBEERESEARCH_Win_Njrat_Strings_Oct_2023 (yara-rule)
  • EMBEERESEARCH_Win_Njrat_Bytecodes_V2_Oct_2023 (yara-rule)
  • EMBEERESEARCH_Win_Njrat_Bytecodes_Oct_2023 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Cobianrat (yara-rule)
  • SEKOIA_Crimeware_Njrat_Strings (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_NAME_RAT_Njrat_0_7D_Modded_Source_Code (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Njrat (yara-rule)

Related threat objects

Reports & references

  • secureworks.com — Copper Fieldstone (report)
  • vectra.ai — Moonlight Middle East Targeted Attacks (report)
  • ecucert.gob.ec — Alerta Apts 2022 03 23 (report)
  • ti.360.net — Analysis Of Apt C 27 (report)
  • MITRE ATT&CK — G0096 (report)
  • Cisco Talos — Sidecopy (report)
  • Kaspersky — 91897 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
  • ESET — Eset Threat Report Q22020 (report)
  • bleepingcomputer.com — Fake Microsoft Teams Updates Lead To Cobalt Strike Deployment (report)
  • intel471.com — Privateloader Malware (report)
  • intezer.com — Intezer 2020 Go Malware Round Up (report)
  • s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
  • s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
  • s3.amazonaws.com — Hashes Iocs For Coverage.Txt (report)
  • s3.amazonaws.com — Network Iocs List For Coverage.Txt (report)
  • intel471.com — China Cybercrime Undergrond Deepmix Tea Horse Road Great Firewall (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)

External references